Fortinet
NSE7_SOC_AR-7.6 · Question #50
Which three factors does the FortiSIEM rules engine use to determine the count when it evaluates the aggregate condition COUNT (Matched Events) on a specific subpattern? (Choose three answers)
The correct answer is A. Group By attributes C. Time window D. Search filter. You've hit your limit · resets 5am (America/New_York)
FortiSIEM Deployment and Configuration
Question
Which three factors does the FortiSIEM rules engine use to determine the count when it evaluates the aggregate condition COUNT (Matched Events) on a specific subpattern? (Choose three answers)
Options
- AGroup By attributes
- BData source
- CTime window
- DSearch filter
- EIncident action
How the community answered
(64 responses)- A70% (45)
- B20% (13)
- E9% (6)
Explanation
You've hit your limit · resets 5am (America/New_York)
Topics
#FortiSIEM rules engine#aggregate conditions#correlation rules#Group By attributes
Community Discussion
No community discussion yet for this question.